[PLACEHOLDER: date], but the page makes
commitments to the people who use it and should be reviewed. It must be re-checked whenever the
architecture changes.
How your journal is kept
A journal is a strange thing to hand to a piece of software. So here’s the whole picture: including a section at the bottom about what we haven’t built yet, because a security page that only lists good news isn’t worth reading.
Your journal is yours alone
Every single query Lapriland makes for your data is filtered by your account first. There is no screen anywhere in the product that shows one person another person’s entries, because there is no code path that would let one exist. Accounts cannot see each other, there is no sharing, no feed, no public profile, and nothing you write can be accidentally published.
Your uploaded photographs are stored outside the public web root and served by a route that checks the file belongs to you. If someone guessed the exact filename of your photograph, they would get a 404.
Signing in
Your password is hashed with bcrypt at a work factor of 12 before it’s stored. We never store it in a readable form, and we genuinely cannot recover it. If we could, so could someone who got hold of the database.
Signing in creates a session cookie, journal.sid. It’s HttpOnly, so scripts can’t read it;
SameSite=Lax; and Secure over HTTPS. It contains a session identifier, nothing more.
Because we can’t recover a password, we replace it instead. Forgot password? emails a single-use link to the address on your account; it expires an hour after it’s issued, and requesting a new one cancels any earlier link. We store only a SHA-256 hash of the token, so the reset table is of no use to anyone who reads it. Whether or not an address has an account here, the page answers the same, it won’t confirm to a stranger that you have one.
In transit
Everything between your browser and Lapriland travels over HTTPS/TLS. So does everything between Lapriland and the AI provider. Nothing about your journal moves over an unencrypted connection.
The AI path, in plain words
When, and only when, you press a button that asks for a reflection:
- Lapriland gathers the entries that reflection needs. Sometimes that’s one entry, sometimes it’s a condensed pass over your whole journal.
- That text is sent over an encrypted connection to a third-party AI provider, reached through a model-routing service, which generates the reflection.
- The reflection comes back and is saved to your account.
And the parts people actually want to know:
- Nothing runs on its own. There is no background analysis, no nightly job that reads your journal, nothing happening while you’re not there. Every AI request is one you started.
- Never using it is a valid choice. The journal, the timeline, journeys, the soundtrack, the echoes between memories, and the full export all work with no AI involvement at all. If you never press those buttons, your writing never leaves our server.
- What we record about each AI action is metadata only: the date, which feature, which model, a token count and a cost. Never the entry text, never the reflection. That’s what the plan meter runs on.
- The provider handles what we send under its own terms. We can’t and won’t promise
things on its behalf.
[PLACEHOLDER: name the provider and link its data-retention terms] - We do not use your entries to train anything, and we don’t sell or share them.
Nobody here reads your journal
There is no admin screen in Lapriland that shows anyone else’s entries. The administrative view that exists is a billing view: which accounts exist, how many entries and how much storage each has, how many AI actions they ran, what those cost us and how many credits they used. Counts and costs, never content.
That’s a statement about the product, and it’s true. Here’s the part that a security page should also say: your entries are stored as ordinary text in an ordinary database, which means that a person with direct access to the production server could technically read them. That is true of nearly every service that isn’t end-to-end encrypted. We don’t have a clever answer to it. We just keep that access tight, we don’t exercise it, and we’d rather tell you than let you assume something warmer.
Getting everything back out
Export is on every plan, always available, and doesn’t need to be requested. From Settings:
- JSON: your entries with all their metadata, plus journeys, life phases and connections
- Full backup zip: that JSON, plus a readable book of your entire journal in plain markdown you can open in anything, plus every image you’ve ever uploaded
The book version matters more than it sounds like it does. It means the value of what you’ve written here isn’t locked to Lapriland existing.
To have everything deleted, use Settings → Data → Delete account (it asks for your
password), or email [PLACEHOLDER: contact email] from your account address.
We delete the account and everything attached to it (entries, images, reflections, journeys, tags), permanently. Export first; we can’t undo it.
What we don’t have yet
An honest list, so you can decide with the real facts.
- Your entries are not encrypted at rest, and Lapriland is not end-to-end encrypted. We’re
not going to claim otherwise.
[PLACEHOLDER: if the host provides full-disk encryption at the volume level, say so here specifically, and don’t overstate what it protects against.] - No two-factor authentication yet. A strong, unique password is currently your only protection. Please use a password manager.
- No formal third-party security audit or certification. Lapriland is a small operation and we’re not going to imply a compliance programme we don’t have.
- Backups.
[PLACEHOLDER: describe your actual backup schedule, retention and encryption status, or state plainly that automated backups are not yet in place. Do not fill this in optimistically. Whatever it says here, please also keep your own export.]
These are on the list. When they’re done, this page changes.
Found something?
If you’ve found a security problem in Lapriland, please tell us before you tell anyone else:
[PLACEHOLDER: [email protected]].
We’ll acknowledge you within [PLACEHOLDER: e.g. 3 working days], keep you updated, and
credit you if you’d like the credit. We won’t pursue legal action against anyone who reports
a genuine issue in good faith and gives us a reasonable chance to fix it before disclosing
it. Please don’t access, modify or delete anyone else’s data while investigating. If you
need an account to test with, ask and we’ll give you one.
We don’t run a paid bug bounty.